Key takeaways
- Anthropic's own documentation says it plainly: "Nothing is added to the text and there are no hidden characters." The watermark is a pattern in which words Claude picked.
- Every tool selling "Claude watermark removal" by stripping zero-width characters is removing something that was never in the text.
- Anthropic's own words on what does work: light editing probably will not remove the watermark completely, but a complete rewrite where every word is replaced will.
- Nobody can currently verify removal on Claude output. The detection API is announced but unreleased, so no tool — ours included — can show you a real before-and-after score.
- EU AI Act Article 50 places the watermarking obligation on AI providers, not on you as an individual using content you generated and own.
What Anthropic actually added to Claude output
On 2 August 2026, Anthropic started embedding a machine-readable watermark in text generated by Claude. It applies to every Claude model launched on or after that date, and it applies worldwide rather than only inside the EU.
The driver is Article 50 of the EU AI Act, which requires providers of generative AI systems to mark synthetic output in a machine-readable way. Anthropic chose to apply it globally rather than maintain two versions of the same model.
What matters for anyone trying to remove it is the shape of the thing. This is not metadata attached to a file, and it is not a set of invisible characters sprinkled through the text. It is a statistical pattern in the words themselves.
Anthropic's own description
"Instead of using an arbitrary random number generator to pick the next word, watermarking uses the key and a few words that come before to settle what word the model should pick." And, decisively: "Nothing is added to the text and there are no hidden characters."
That second sentence is the one to hold on to. It rules out an entire category of tool in a single line, and it comes from the company that built the watermark.
How the SynthID watermark works
Anthropic uses SynthID-Text, the approach Google DeepMind published in Nature in 2024. The underlying idea traces back to a 2022 proposal by Scott Aaronson.
When a language model writes, it is repeatedly choosing the next token from a ranked list of candidates. Usually that choice involves a random element. Watermarking replaces the arbitrary randomness with a value derived from a secret key plus the few words immediately preceding. Across a long enough passage, the choices drift in a direction that looks unremarkable to a reader but is measurable to anyone holding the key.
That design explains the watermark's strengths and its weaknesses, and both matter if you are trying to get rid of it.
| Property | Why | What it means for you |
|---|---|---|
| Survives copy and paste | The signal is the word choice, not the encoding | Moving text between apps changes nothing |
| Survives translation | Claude chose every word in the source | Round-tripping through another language is not a reliable escape |
| Weak on short passages | Too few token choices to accumulate a signal | A paragraph carries far less evidence than a full essay |
| Sparser on factual passages | Constrained text has few valid alternatives to bias | Technical and factual writing is marked more lightly |
| No hidden characters | Nothing is inserted into the text at all | Character-stripping tools have nothing to find |
The last two rows are also why detection is probabilistic rather than binary. A watermark detector returns a confidence score over a passage, not a yes-or-no verdict on a sentence.
Does Claude watermark code?
This is the question developers have asked loudest since the rollout, and it has a specific answer rather than a reassuring one.
Code carries less watermarking than prose, for the same reason factual writing does: the mark is encoded by choosing between equally valid alternatives, and code offers far fewer of them. A function that has to compile, pass its tests and use the names already defined around it leaves the model very little room to pick a different token without changing behaviour. There is nowhere to hide a signal.
That is not a carve-out. Anthropic has not said code is excluded from watermarking — it has said code has fewer opportunities to mark. The distinction matters, because the discretionary text inside a file is a different story.
Where a signal can still sit in a code file
Comments, docstrings, commit messages, README and documentation text, error strings, and variable or function names where several equally good options existed. These are the parts of a file where the model genuinely had a choice, and they are exactly the parts that read like prose.
So a tightly constrained implementation function is close to unmarkable, while a heavily commented module or a generated README sits much closer to ordinary prose. Detection also needs volume, and a short snippet gives a detector very little to work with.
The second mark: C2PA metadata on files
Anthropic uses two complementary techniques, and almost every article about removal only covers the first. Alongside the text watermark, it attaches signed provenance metadata to files, following the C2PA open standard.
These behave in opposite ways, which is why lumping them together produces such bad advice.
| Text watermark | C2PA metadata | |
|---|---|---|
| Where it lives | In the word choices themselves | Attached to the file, not the content |
| Survives copy and paste | Yes | No — copying the text out leaves it behind |
| Can you strip it? | No, only rewrite it | Yes — a re-save or format conversion drops it |
| Can you verify it is gone? | Not today — no public detector | Yes — metadata is readable with any C2PA tool |
Anthropic also lists three conditions under which either mark may simply not be detectable: the text has been heavily edited, paraphrased, translated or mixed into other writing; the passage is very short, leaving too little signal; or it came through a platform or file type where that marking type was not supported.
Why zero-width character removers do nothing here
Search for a Claude watermark remover and most of what comes back is a text box that scans for invisible Unicode — zero-width spaces, zero-width joiners, byte-order marks, exotic space characters — and deletes them. Several of these sites appeared within days of Anthropic's announcement.
Those tools are not lying about what they do. They genuinely find and remove invisible characters. The problem is that Claude's watermark is not made of invisible characters, so removing invisible characters cannot remove it.
What a green checkmark actually means
When one of these tools reports "watermark removed" on Claude text, it is telling you it found no zero-width characters. That was true before you pasted the text in. The statistical pattern it did not look at is still there.
This is not a fringe complaint. BleepingComputer's assessment of the wave of new tools was blunt: AI watermark removers flooded the web, and almost none of them can prove they work. An independent researcher testing popular text cleaners found one let the most common hidden-payload technique through untouched.
There is a real use for these cleaners, and it is worth being fair about it: chat interfaces do sometimes leave invisible characters in text you copy out of them. That is a genuine artefact worth cleaning. It is simply a different problem from the one Anthropic introduced in August.
The distinction, laid out properly:
- The three different things called an AI watermark — statistical, invisible Unicode, and file metadata
- ChatGPT watermark remover — where character cleaning is actually the right answer
What actually removes a SynthID watermark
Anthropic, on what defeats it
"Light editing probably won't remove the watermark completely; a complete rewrite where every word is replaced will."
The mechanism makes the reason obvious. The evidence is the sequence of choices Claude made. Replace a choice and you replace the evidence for it. Replace some of them and you weaken the signal without eliminating it, because a detector aggregates across the whole passage — a partially rewritten essay can still carry enough marked stretches to score above threshold.
Anthropic's support documentation similarly acknowledges that heavy editing, paraphrasing and translation degrade the mark. That is a meaningfully different claim from "paste it into a cleaner and it is gone".
Changes the signal
- A full paraphrase. Every sentence re-expressed with different word choices. This is the case Anthropic explicitly names.
- Sentence-level restructuring. Splitting, merging and reordering sentences changes both the tokens and the context each subsequent choice is keyed against.
- Substantive manual rewriting. Rewriting in your own voice, with your own examples. Slower than any tool, and the only version nobody can dispute.
Does not change the signal
- Stripping invisible characters. There are none to strip. Anthropic's documentation is explicit on this point.
- Find-and-replace on em dashes or stock phrases. Swapping punctuation and a handful of giveaway words leaves the overwhelming majority of token choices untouched.
- Changing formatting, fonts or file type. The watermark is in the words. Re-saving as a different file format carries it along unchanged.
How RewriteAI's rewrite engine handles this
RewriteAI is a full-rewrite paraphrase engine. It is not a character filter and it does not scan for hidden marks. It takes a passage and re-expresses it, replacing word choices across the text — which is the mechanism Anthropic names.
What we are not claiming
We do not claim guaranteed watermark removal. Anthropic's detection API is not public, so no tool — ours included — can currently show you a verified before-and-after SynthID score on Claude output. Anyone who tells you otherwise cannot back it up either. What we can tell you is what the engine does: it replaces the words.
Free plan: 500 words per month, 300 words per request, English only, account required.
If you are going to do this, do it properly
Longer inputs and a stronger paraphrase setting replace more of the token choices. Rewriting two sentences out of a 900-word essay leaves almost all of the original signal in place.
Can anyone verify a Claude watermark was removed?
Not on Claude output, and not today. Anthropic has said it will offer a watermark detection API and is working out the implementation details, but it has not shipped. Until it does, nobody outside Anthropic can measure whether a given passage still carries the mark.
That is an uncomfortable thing for a page like this to admit, and it is why the rest of the market does not admit it. Every confident claim you have read this month about defeating Anthropic's watermark — ours included — is currently unfalsifiable.
There is a partial way around it. Google's SynthID-Text reference implementation is open source, including both the Weighted Mean and Bayesian detectors described in the Nature paper. That lets us generate watermarked text under a key we control, rewrite it, and measure the detector's confidence before and after.
The benchmark we are running, stated in advance
Generate watermarked and unwatermarked passages using the open SynthID-Text implementation. Pass the watermarked set through our rewrite engine. Score all three sets with the Bayesian detector and publish the distributions and the detection rate at a stated false-positive rate. The limitation, stated up front: this measures the open reference implementation under our own key, not Anthropic's production configuration. It is a directional proxy, not proof about Claude.
We will publish the numbers in this section when they exist, including if they are unflattering.
Is removing a Claude watermark legal?
The obligation that created this watermark sits on Anthropic, not on you. EU AI Act Article 50 requires providers of generative AI systems to mark synthetic output, and the penalties attached to it — up to €15 million or 3% of global annual turnover — apply to providers and to organisations deploying AI professionally.
An individual who generated some text and owns it is not under a legal duty to preserve a provider's watermark on it. Removing a mark from your own content is not, in itself, an offence under Article 50.
Two things sit outside that. If you publish realistic synthetic media — a deepfake-style image or video that could pass for a real person or event — you may carry your own disclosure obligation regardless of who generated it. And separately from the law entirely, whatever your university, employer or client requires of you is a matter of their rules and your agreement with them.
Not legal advice
This is a summary of how the obligation is structured, not advice on your situation. Rules vary by jurisdiction and are still settling.
When you should not remove it
There are cases where removing the mark is the wrong call, and pretending otherwise would make this page less useful.
Leave it, or disclose instead:
- Academic work submitted under a disclosure policy. The question is not whether the watermark is detectable — it is what you agreed to when you enrolled. Disclose the assistance.
- Synthetic media depicting real people or events. Provenance signals exist for a reason here, and stripping them is the case the transparency rules were written for.
- Anything where a reader's decision depends on believing a human wrote it unaided — expert testimony, medical or legal guidance, first-person reporting.
Reasonable cases for a rewrite:
- Commercial copy you own, where a model produced a first draft and the finished text is your product.
- Drafts you have already rewritten substantively, where a residual mark misrepresents how the text was actually made.
- Internal documents where an automated provenance flag would create a misleading record of authorship.
Sources
- How Claude's text watermarking works — Anthropic
- How Claude marks AI-generated content — Anthropic Help Center
- Scalable watermarking for identifying large language model outputs — Nature, Google DeepMind
- Article 50: Transparency obligations for providers and deployers — EU AI Act
- AI watermark removers flood the web. Almost none can prove they work. — BleepingComputer